FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Change crawler invocation to not compile everything first. Add more · ghdevnull/BenchmarkJava@e457c9a · GitHub

Commit e457c9a

Browse files
committed
Change crawler invocation to not compile everything first. Add more
memory when running Fortify scan and update a couple tool specific parsers.
1 parent becbdcf commit e457c9a

7 files changed

Lines changed: 35 additions & 12 deletions

File tree

‎pom.xml‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,12 +35,16 @@
3535
<version>${version.exec.maven}</version>
3636
<executions>
3737
<execution>
38-
<phase>compile</phase>
38+
<phase>validate</phase>
3939
<goals>
4040
<goal>java</goal>
4141
</goals>
4242
<configuration>
4343
<mainClass>org.owasp.benchmark.tools.BenchmarkCrawler</mainClass>
44+
<arguments>
45+
<argument>${addlArg1}</argument> <!-- -f here -->
46+
<argument>${addlArg2}</argument> <!-- filename here -->
47+
</arguments>
4448
</configuration>
4549
</execution>
4650
</executions>

‎runCrawler.bat‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,2 @@
1-
call mvn compile -Pcrawler
1+
CALL mvn validate -Pcrawler
2+

‎runCrawler.sh‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
#!/bin/sh
2-
mvn compile -Pcrawler
2+
mvn validate -Pcrawler
33

‎scripts/mvnFortifyScan.bat‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
sourceanalyzer -b benchmark -Xmx6G -scan -f benchmark.fpr
1+
sourceanalyzer -b benchmark -Xmx10G -scan -f benchmark.fpr
22

‎src/main/java/org/owasp/benchmark/score/parsers/ContrastReader.java‎

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -159,10 +159,19 @@ private void parseContrastJavaFinding(TestSuiteResults tr, String json) throws E
159159
String uri = request.getString("uri");
160160

161161
if (tcr.getCWE() != 0 && uri.contains(BenchmarkScore.TESTCASENAME)) {
162-
String testNumber =
162+
// Normal uri's look like: "uri":"/benchmark/cmdi-00/BenchmarkTest00215", but for
163+
// web services, they can look like:
164+
// "uri":"/benchmark/rest/xxe-00/BenchmarkTest03915/send"
165+
String testNumberStr =
163166
uri.substring(
164-
uri.lastIndexOf('/') + BenchmarkScore.TESTCASENAME.length() + 1);
165-
tcr.setNumber(Integer.parseInt(testNumber));
167+
uri.indexOf(BenchmarkScore.TESTCASENAME)
168+
+ BenchmarkScore.TESTCASENAME.length());
169+
// At this point testNumber could contain '00215', or '03915/send'
170+
int slashIndex = testNumberStr.indexOf('/');
171+
if (slashIndex > 0) {
172+
testNumberStr = testNumberStr.substring(0, slashIndex);
173+
}
174+
tcr.setNumber(Integer.parseInt(testNumberStr));
166175
// System.out.println( tcr.getNumber() + "\t" + tcr.getCWE() + "\t" +
167176
// tcr.getCategory() );
168177
tr.put(tcr);

‎src/main/java/org/owasp/benchmark/score/parsers/FortifyReader.java‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -161,6 +161,9 @@ private static TestCaseResult parseFortifyVulnerability(Node vuln) {
161161
private static int cweLookup(String vtype, String subtype, Node unifiedNode) {
162162

163163
switch (vtype) {
164+
case "Access Control":
165+
return 284;
166+
164167
case "Command Injection":
165168
return 78;
166169

@@ -189,6 +192,8 @@ private static int cweLookup(String vtype, String subtype, Node unifiedNode) {
189192
return 00;
190193
case "Denial of Service":
191194
return 400;
195+
case "Dynamic Code Evaluation":
196+
return 95;
192197
case "Header Manipulation":
193198
return 113;
194199
case "Hidden Field":
@@ -205,6 +210,7 @@ private static int cweLookup(String vtype, String subtype, Node unifiedNode) {
205210
return 915;
206211

207212
case "Missing Check against Null":
213+
case "Missing Check for Null Parameter":
208214
return 476;
209215

210216
case "Missing XML Validation":
@@ -303,6 +309,7 @@ private static int cweLookup(String vtype, String subtype, Node unifiedNode) {
303309
case "Hardcoded Domain in HTML":
304310
case "J2EE Bad Practices":
305311
case "J2EE Misconfiguration":
312+
case "Object Model Violation":
306313
case "Poor Style":
307314
case "Portability Flaw":
308315
case "Race Condition":

‎src/main/java/org/owasp/benchmark/tools/BenchmarkCrawler.java‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -182,27 +182,29 @@ protected ResponseInfo sendRequest(
182182
private static File processCommandLineArgs(String[] args) {
183183

184184
String crawlerFileName = Utils.DATA_DIR + "benchmark-crawler-http.xml"; // default location
185-
File crawlerFile = null;
185+
File crawlerFile = new File(crawlerFileName); // default location;
186186

187187
if (args == null || args.length == 0) {
188188
// No arguments is OK
189-
crawlerFile = new File(crawlerFileName); // default location
190189
} else if (args.length != 0 && args.length != 2) {
191190
System.out.println("Usage: no arguments or -f /PATH/TO/TESTSUITE-crawler-http.xml");
191+
return null;
192192
} else if (args.length == 2) {
193193
if ("-f".equalsIgnoreCase(args[0])) {
194194
// -f indicates use the specified crawler file
195195
crawlerFileName = args[1];
196196
crawlerFile = new File(crawlerFileName);
197197
} else if (!(args[0] == null
198198
&& args[1] == null)) { // pom settings for crawler forces creation of 2 args,
199-
// but if none are provided, they are null
200199
System.out.println("Supported options: -f /PATH/TO/TESTSUITE-crawler-http.xml");
200+
return null;
201201
}
202202
}
203-
if (crawlerFile != null && !crawlerFile.exists()) {
203+
if (!crawlerFile.exists()) {
204204
System.out.println(
205-
"ERROR: Crawler Configuration file: '" + crawlerFileName + "' not found!");
205+
"ERROR: Crawler Configuration file: '"
206+
+ crawlerFile.getAbsolutePath()
207+
+ "' not found!");
206208
crawlerFile = null;
207209
}
208210

0 commit comments

Comments
 (0)

Back | FazBrowse Home | New Git URL